<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Open source on</title><link>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/open-source/</link><description>Recent content in Open source on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Tue, 06 Oct 2020 08:48:23 +0000</lastBuildDate><atom:link href="https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/open-source/index.xml" rel="self" type="application/rss+xml"/><item><title>Octo STS</title><link>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/open-source/octo-sts/</link><pubDate>Sat, 20 Dec 2025 08:49:15 +0000</pubDate><guid>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/open-source/octo-sts/</guid><description>&lt;p&gt;Octo STS is an open source GitHub App, developed by Chainguard, that acts as a security token service for the GitHub API. It exchanges OIDC tokens from your workloads for short-lived GitHub tokens, so your automation doesn&amp;rsquo;t need long-lived personal access tokens (PATs).&lt;/p&gt;
&lt;p&gt;To learn why PATs are risky and how Octo STS replaces them, read &lt;a href="https://www.chainguard.dev/supply-chain-security-101/octo-sts-overview"&gt;Octo STS: Short-lived GitHub tokens without PATs&lt;/a&gt; in Supply Chain Security 101. To install and configure it, follow &lt;a href="https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/open-source/octo-sts/set-up-octo-sts/"&gt;Set up and use Octo STS&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Build tools</title><link>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/open-source/build-tools/</link><pubDate>Thu, 02 May 2024 08:49:15 +0000</pubDate><guid>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/open-source/build-tools/</guid><description>&lt;p&gt;The open source tools that were developed for the &lt;a href="https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/open-source/wolfi/"&gt;Wolfi&lt;/a&gt; operating system.&lt;/p&gt;</description></item><item><title>SBOMs</title><link>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/open-source/sbom/</link><pubDate>Thu, 26 Jan 2023 08:49:15 +0000</pubDate><guid>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/open-source/sbom/</guid><description>&lt;p&gt;A software bill of materials, or an SBOM (pronounced s-bomb), is a key resource for enabling visibility into the different software components of a codebase.&lt;/p&gt;</description></item><item><title>Wolfi</title><link>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/open-source/wolfi/</link><pubDate>Mon, 05 Sep 2022 08:49:15 +0000</pubDate><guid>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/open-source/wolfi/</guid><description>&lt;p&gt;Wolfi is a Linux &lt;em&gt;undistro&lt;/em&gt; built for containers. It uses the apk package format, builds every package from source, and relies on the container runtime to provide the kernel. Chainguard Containers are built on Wolfi.&lt;/p&gt;
&lt;p&gt;To learn what Wolfi is and why Chainguard built it, read &lt;a href="https://www.chainguard.dev/supply-chain-security-101/wolfi-overview"&gt;What is Wolfi?&lt;/a&gt; in Supply Chain Security 101. The pages in this section show you how to work with Wolfi.&lt;/p&gt;
&lt;h2 id="try-wolfi" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Try Wolfi&lt;/span&gt;
&lt;a href="#try-wolfi" class="anchor" aria-label="Link to Try Wolfi" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;To explore Wolfi, run the &lt;a href="https://images.chainguard.dev/directory/image/wolfi-base/overview"&gt;wolfi-base&lt;/a&gt; image. It&amp;rsquo;s intentionally minimal: it contains the Wolfi filesystem, the apk package manager, and a shell.&lt;/p&gt;</description></item><item><title>Sigstore</title><link>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/open-source/sigstore/</link><pubDate>Tue, 06 Oct 2020 08:49:15 +0000</pubDate><guid>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/open-source/sigstore/</guid><description/></item></channel></rss>